apu — Agreement PartyUInfo
Location: header · Format: string
Base64url-encoded, application-supplied context information about the message originator, used as input to ECDH-ES key derivation (Concat KDF). Optional; when present it must match on both sides of the agreement or the derived key will differ.
Defined in RFC 7518 §4.6.1.2.
Decode a JWT and inspect its apu claim in the TokenPrism debugger — free, entirely in your browser.